
VLAN-backed subnets: A VPC subnet can now attach directly to a physical VLAN, giving workloads the same L2 connectivity as a distributed port group. “As a result, even if it’s in the same VPC, it can only reach the public subnets,” Tallet said. A variant, available only with a distributed external connection, also attaches the subnet to the VPC gateway, so the default gateway exists in both worlds at once.
VPC connectivity policies: Modeled on Cisco’s private VLAN concept, these control which VPCs within a tenant can reach each other. VPCs default to open communication. Administrators can group VPCs into communities, mark one promiscuous so it reaches every VPC in the tenant, or isolated so it reaches only promiscuous VPCs.
Native EVPN VXLAN support: VCF 9.0’s distributed external connection let ESXi hosts send north-south traffic straight to the physical infrastructure over VLAN, skipping the NSX edge, but required a single L2 VLAN across every host involved. VCF 9.1 extends that model to VXLAN fabrics through EVPN, using a small route controller VM to handle the BGP EVPN control plane. “It’s not an edge, it is only running BGP. There is no data path,” Tallet said.




















